Two-Way Security Policy and Audit Log Tracking System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to efficiently inquire, collate, and track security policies and audit logs in real-time, making it difficult to analyze and respond to hacking and security invasion incidents.

Innovation Solution

A system and method that utilize a security policy setting unit, security software agent, audit log collection unit, and two-way inquiry tracking unit to record and manage security policies and audit logs with unique policy identification information, enabling two-way inquiry, collation, and tracking of security policies and audit logs in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If log files are collected and stored without policy association, then log storage is simple, but it becomes impossible to analyze the cause of security incidents by comparing logs with security policies

Engineering Contradiction:
Improvepolicy-log association informationVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system performs preliminary action by associating policy identification information with audit logs at the time of log generation, rather than attempting to associate them later during analysis. The security policy setting unit assigns unique policy IDs to policies, and the security software agent includes these IDs in generated audit logs, ensuring policy-log associations are established before any analysis occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces policy identification information as an intermediary element that bridges security policies and audit logs. This intermediary consists of unique policy IDs assigned to policies and included in corresponding audit logs, enabling efficient association without direct complex linking between entire policy documents and log files.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If managers analyze log files by comparing with security policies one by one, then analysis is thorough, but it takes a long time and is economically inefficient

Engineering Contradiction:
Improveanalysis accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system creates a copy of the policy identification information within the audit log itself. Instead of requiring managers to access and compare entire security policy documents, the unique policy ID embedded in each audit log serves as a compact reference that can be quickly matched against stored policy information, dramatically reducing analysis time while maintaining accuracy.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary organization of policy-log associations by embedding policy IDs in audit logs during log generation. This preliminary structuring eliminates the need for time-consuming manual comparison during incident analysis, as the associations are already established and can be retrieved instantly.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the system does not track policy changes over time, then the system is simpler, but it cannot inquire and confirm past security policies and logs that were set in the past

Engineering Contradiction:
Improvetemporal inquiry capabilityVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by recording policy identification information along with policy configuration details in the integrated security policy history database whenever policies are generated or changed. This historical recording enables retrospective inquiry of past policies and their associated logs without adding complex temporal tracking mechanisms during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The policy identification information serves as a stable intermediary that links past security policies with their corresponding audit logs across different time periods. By including policy IDs in both the history database and audit logs, the system enables temporal associations without requiring complex time-based tracking of policy changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Quantity of substance

If various security related logs increase exponentially, then comprehensive logging is achieved, but it becomes very difficult to clearly compare and analyze the policy generating the corresponding log

Engineering Contradiction:
Improvelog volumeVSAvoidpolicy identification difficulty
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The system embeds a compact copy of the policy identification (unique policy ID) directly within each audit log. This allows exponential growth in log volume while maintaining constant-time policy identification, as managers only need to match the small policy ID field against the integrated security policy history database rather than analyzing entire policy documents for each log entry.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system extracts the essential policy identification element (unique policy ID) from the full security policy and places it within the audit log. This extraction creates a lightweight reference that enables efficient filtering and analysis of large volumes of logs by policy, without requiring the full policy content to be stored or processed with each log entry.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12287870B2Security policy and audit log two way inquiry, collation, and tracking system and method
Publication Date: 2025.04.29 SECUVE CO LTD
  • US12287870B2 patent drawing
  • US12287870B2 patent drawing
  • US12287870B2 patent drawing

AI summary

The present invention relates to a security policy and audit log two-way inquiry, collation, and tracking system and method capable of effectively inquiring and confirming various pieces of log information generated due to setting and change of various security policies, and capable of inquiring and confirming a security policy related to log information based on the collected log information. According to the present invention, it is possible to inquire, collate, and track logs generated and recorded by the various security policies, it is possible to inquire, collate, and track the security policy applied to the collected log, and it is possible to inquire, collate, and track the security policy and the log in two ways and in real time.